CVE-2025-38430
A flaw in the Linux kernel’s NFS server could let an attacker send a malformed request that causes undefined behavior. The issue was fixed by adding a check that the request is a valid NFSv4 compound operation. The vulnerability is now resolved in updated kernel releases.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, including Debian Linux 11.0.
Real-world impact
An attacker could potentially crash the NFS server or execute arbitrary code, leading to denial of service or compromise of the affected system.
Why this severity
The CVSS score of 9.8 reflects that the flaw can be exploited remotely without authentication, with no user interaction, and can lead to complete compromise of confidentiality, integrity, and availability.
What to do about it
- 011. Update the Linux kernel to a version that includes the patch that checks for NFSPROC4_COMPOUND in nfsd4_spo_must_allow().
- 022. Reboot the system to load the new kernel.
NVD description indicates the vulnerability has been resolved.
Timeline
- Jul 25, 2025 · Jul 25, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 7d agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 6d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/1244f0b2c3cecd3f34…patch
- git.kernel.org/stable/c/2c54bd5a380ebf646f…patch
- git.kernel.org/stable/c/425efc6b3292a3c79b…patch
- git.kernel.org/stable/c/64a723b0281ecaa59d…patch
- git.kernel.org/stable/c/7a75a956692aa64211…patch
- git.kernel.org/stable/c/b1d0323a09a29f8157…patch
- git.kernel.org/stable/c/bf78a2706ce975981e…patch
- git.kernel.org/stable/c/e7e943ddd1c6731812…patch
- lists.debian.org/debian-lts-announce/2025/10…third party advisory
- lists.debian.org/debian-lts-announce/2025/10…third party advisory
- cert-portal.siemens.com/productcert/html/ssa-082556…